Skip to content

Commit 56c6888

Browse files
Chore(deps): Bump the action-dependencies group across 1 directory with 6 updates
Bumps the action-dependencies group with 6 updates in the / directory: | Package | From | To | | --- | --- | --- | | [actions/checkout](https://github.com/actions/checkout) | `4.2.2` | `5.0.0` | | [github/codeql-action](https://github.com/github/codeql-action) | `3` | `4` | | [actions/setup-node](https://github.com/actions/setup-node) | `4.1.0` | `5.0.0` | | [aquasecurity/trivy-action](https://github.com/aquasecurity/trivy-action) | `0.28.0` | `0.33.1` | | [ossf/scorecard-action](https://github.com/ossf/scorecard-action) | `2.4.1` | `2.4.3` | | [actions/upload-artifact](https://github.com/actions/upload-artifact) | `4.4.3` | `4.6.2` | Updates `actions/checkout` from 4.2.2 to 5.0.0 - [Release notes](https://github.com/actions/checkout/releases) - [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md) - [Commits](actions/checkout@v4.2.2...v5.0.0) Updates `github/codeql-action` from 3 to 4 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@v3...v4) Updates `actions/setup-node` from 4.1.0 to 5.0.0 - [Release notes](https://github.com/actions/setup-node/releases) - [Commits](actions/setup-node@v4.1.0...v5.0.0) Updates `aquasecurity/trivy-action` from 0.28.0 to 0.33.1 - [Release notes](https://github.com/aquasecurity/trivy-action/releases) - [Commits](aquasecurity/trivy-action@0.28.0...0.33.1) Updates `ossf/scorecard-action` from 2.4.1 to 2.4.3 - [Release notes](https://github.com/ossf/scorecard-action/releases) - [Changelog](https://github.com/ossf/scorecard-action/blob/main/RELEASE.md) - [Commits](ossf/scorecard-action@v2.4.1...v2.4.3) Updates `actions/upload-artifact` from 4.4.3 to 4.6.2 - [Release notes](https://github.com/actions/upload-artifact/releases) - [Commits](actions/upload-artifact@v4.4.3...v4.6.2) --- updated-dependencies: - dependency-name: actions/checkout dependency-version: 5.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: action-dependencies - dependency-name: github/codeql-action dependency-version: '4' dependency-type: direct:production update-type: version-update:semver-major dependency-group: action-dependencies - dependency-name: actions/setup-node dependency-version: 5.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: action-dependencies - dependency-name: aquasecurity/trivy-action dependency-version: 0.33.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: action-dependencies - dependency-name: ossf/scorecard-action dependency-version: 2.4.3 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: action-dependencies - dependency-name: actions/upload-artifact dependency-version: 4.6.2 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: action-dependencies ... Signed-off-by: dependabot[bot] <support@github.com>
1 parent 91b6068 commit 56c6888

File tree

4 files changed

+21
-21
lines changed

4 files changed

+21
-21
lines changed

.github/workflows/codeql-analysis.yml

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -13,7 +13,7 @@ jobs:
1313

1414
steps:
1515
- name: Checkout repository
16-
uses: actions/checkout@v4.2.2
16+
uses: actions/checkout@v5.0.0
1717
with:
1818
# We must fetch at least the immediate parents so that if this is
1919
# a pull request then we can checkout the head.
@@ -26,15 +26,15 @@ jobs:
2626

2727
# Initializes the CodeQL tools for scanning.
2828
- name: Initialize CodeQL
29-
uses: github/codeql-action/init@v3
29+
uses: github/codeql-action/init@v4
3030
# Override language selection by uncommenting this and choosing your languages
3131
# with:
3232
# languages: go, javascript, csharp, python, cpp, java
3333

3434
# Autobuild attempts to build any compiled languages (C/C++, C#, or Java).
3535
# If this step fails, then you should remove it and run the build manually (see below)
3636
- name: Autobuild
37-
uses: github/codeql-action/autobuild@v3
37+
uses: github/codeql-action/autobuild@v4
3838

3939
# ℹ️ Command-line programs to run using the OS shell.
4040
# 📚 https://git.io/JvXDl
@@ -48,4 +48,4 @@ jobs:
4848
# make release
4949

5050
- name: Perform CodeQL Analysis
51-
uses: github/codeql-action/analyze@v3
51+
uses: github/codeql-action/analyze@v4

.github/workflows/main.yml

Lines changed: 11 additions & 11 deletions
Original file line numberDiff line numberDiff line change
@@ -24,10 +24,10 @@ jobs:
2424

2525
steps:
2626
- name: Make checkout
27-
uses: actions/checkout@v4.2.2
27+
uses: actions/checkout@v5.0.0
2828

2929
- name: Use Node.js 24.8.0
30-
uses: actions/setup-node@v4.1.0
30+
uses: actions/setup-node@v6.0.0
3131
with:
3232
node-version: 24.8.0
3333

@@ -43,10 +43,10 @@ jobs:
4343

4444
steps:
4545
- name: Make checkout
46-
uses: actions/checkout@v4.2.2
46+
uses: actions/checkout@v5.0.0
4747

4848
- name: Use Node.js 24.8.0
49-
uses: actions/setup-node@v4.1.0
49+
uses: actions/setup-node@v6.0.0
5050
with:
5151
node-version: 24.8.0
5252

@@ -62,7 +62,7 @@ jobs:
6262

6363
steps:
6464
- name: Make checkout
65-
uses: actions/checkout@v4.2.2
65+
uses: actions/checkout@v5.0.0
6666

6767
- name: Lint `./README.md`
6868
uses: avto-dev/markdown-lint@v1.5.0
@@ -82,10 +82,10 @@ jobs:
8282

8383
steps:
8484
- name: Make checkout
85-
uses: actions/checkout@v4.2.2
85+
uses: actions/checkout@v5.0.0
8686

8787
- name: Use Node.js 24.8.0
88-
uses: actions/setup-node@v4.1.0
88+
uses: actions/setup-node@v6.0.0
8989
with:
9090
node-version: 24.8.0
9191

@@ -101,10 +101,10 @@ jobs:
101101

102102
steps:
103103
- name: Make checkout
104-
uses: actions/checkout@v4.2.2
104+
uses: actions/checkout@v5.0.0
105105

106106
- name: Use Node.js 24.8.0
107-
uses: actions/setup-node@v4.1.0
107+
uses: actions/setup-node@v6.0.0
108108
with:
109109
node-version: 24.8.0
110110

@@ -126,7 +126,7 @@ jobs:
126126

127127
steps:
128128
- name: Make checkout
129-
uses: actions/checkout@v4.2.2
129+
uses: actions/checkout@v5.0.0
130130

131131
- name: Set tag var
132132
id: vars
@@ -136,7 +136,7 @@ jobs:
136136
run: docker build . --file Dockerfile --build-arg TARGET=production --tag angular-ngrx-frontend:${{ steps.vars.outputs.DOCKER_TAG }}
137137

138138
- name: Run Trivy vulnerability scanner
139-
uses: aquasecurity/trivy-action@0.29.0
139+
uses: aquasecurity/trivy-action@0.33.1
140140
with:
141141
image-ref: 'angular-ngrx-frontend:${{ steps.vars.outputs.DOCKER_TAG }}'
142142
format: 'table'

.github/workflows/scorecard.yml

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -34,12 +34,12 @@ jobs:
3434

3535
steps:
3636
- name: "Checkout code"
37-
uses: actions/checkout@v4.2.2
37+
uses: actions/checkout@v5.0.0
3838
with:
3939
persist-credentials: false
4040

4141
- name: "Run analysis"
42-
uses: ossf/scorecard-action@v2.4.1
42+
uses: ossf/scorecard-action@v2.4.3
4343
with:
4444
results_file: results.sarif
4545
results_format: sarif
@@ -61,14 +61,14 @@ jobs:
6161
# Upload the results as artifacts (optional). Commenting out will disable uploads of run results in SARIF
6262
# format to the repository Actions tab.
6363
- name: "Upload artifact"
64-
uses: actions/upload-artifact@v4.4.3
64+
uses: actions/upload-artifact@v5.0.0
6565
with:
6666
name: SARIF file
6767
path: results.sarif
6868
retention-days: 5
6969

7070
# Upload the results to GitHub's code scanning dashboard.
7171
- name: "Upload to code-scanning"
72-
uses: github/codeql-action/upload-sarif@v3
72+
uses: github/codeql-action/upload-sarif@v4
7373
with:
7474
sarif_file: results.sarif

.github/workflows/vulnerability-scan.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -13,13 +13,13 @@ jobs:
1313
runs-on: ubuntu-latest
1414

1515
steps:
16-
- uses: actions/checkout@v4.2.2
16+
- uses: actions/checkout@v5.0.0
1717

1818
- name: Build the Docker image
1919
run: docker build . --file Dockerfile --tag angular-ngrx-frontend:master
2020

2121
- name: Scan image with trivy
22-
uses: aquasecurity/trivy-action@0.28.0
22+
uses: aquasecurity/trivy-action@0.33.1
2323
with:
2424
image-ref: angular-ngrx-frontend:master
2525
ignore-unfixed: 'true'

0 commit comments

Comments
 (0)